Executive brief
The Kids Life theme for WordPress, commonly used for school and childcare websites, contains a security flaw that allows attackers to inject malicious scripts into the site. If a site administrator or visitor clicks a specially crafted link, the attacker could steal login sessions, redirect users to malicious websites, or deface the site. This vulnerability can be exploited by anyone on the internet without needing an account on the affected website.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Kids Life | Children School WordPress theme (versions <= 5.2) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a user to interact with a malicious link or crafted page (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized actions on behalf of a logged-in user, or delivery of malicious payloads to site visitors. As of the advisory date, no official patch has been released by the vendor.
Affected products
- Designthemes Kids Life | Children School WordPress Theme <= 5.2
Timeline
- 2025-11-07: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-06-30: advisory: Patchstack published advisory details
- 2026-07-02: disclosed: CVE published to NVD dataset